
RaCar Message Me Security & Risk Analysis
wordpress.org/plugins/racar-message-meRaCar Message Me allows you to add a customizable button with the social networks you set up.
Is RaCar Message Me Safe to Use in 2026?
Generally Safe
Score 100/100RaCar Message Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "racar-message-me" v1.0.5 plugin exhibits a generally good security posture based on the provided static analysis. It demonstrates strong adherence to secure coding practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping the vast majority (87%) of its output. The absence of file operations and external HTTP requests further reduces potential attack vectors. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, suggesting a history of stable and secure development.
However, there are a few areas that warrant attention. The plugin has a total of one entry point through a shortcode, and while the analysis indicates it's unprotected, the nature of this shortcode is not detailed. More importantly, the static analysis reveals the complete absence of nonce checks and a low number of capability checks (only 2). This lack of robust authentication and authorization mechanisms, especially for its single entry point, presents a potential security weakness. If the shortcode handles any user-provided data, it could be susceptible to various attacks without proper validation and permission enforcement.
In conclusion, the "racar-message-me" plugin has several strengths, including its clean code regarding SQL and output escaping, and a spotless vulnerability history. Nevertheless, the reliance on minimal capability checks and the apparent lack of nonce checks on its shortcode create a notable risk. Future development should prioritize implementing more comprehensive authentication and authorization for all entry points to enhance its overall security.
Key Concerns
- No nonce checks implemented
- Low number of capability checks
- Unprotected shortcode entry point
RaCar Message Me Security Vulnerabilities
RaCar Message Me Code Analysis
Output Escaping
RaCar Message Me Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
RaCar Message Me Maintenance & Trust
Maintenance Signals
Community Trust
RaCar Message Me Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
Contactus
contactus
Free website widget for chatting with your visitors via WhatsApp, Facebook Messenger, Viber and Telegram.
Push Anything To Social
phongmy-push-anything-to-social
This's plugins help Owner push order from Woocommerce to Facebook messenger quickly base On CallmeBot API
Smartarget Contact Us – All in one
smartarget-contact-us-all-in-one
Add all contact us in one click: Whatsapp, Messenger, Email, etc
RaCar Message Me Developer Profile
3 plugins · 410 total installs
How We Detect RaCar Message Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/racar-message-me/css/rmm-stylesheet.css/wp-content/plugins/racar-message-me/js/rmm-javascript.js/wp-content/plugins/racar-message-me/js/rmm-javascript.jsHTML / DOM Fingerprints
rmm-btn-floatdata-iddata-toggledata-targetrmm_vars